diff --git a/adm/shop_admin/itemformupdate.php b/adm/shop_admin/itemformupdate.php index 35a2ffffd..dd8ba58a4 100644 --- a/adm/shop_admin/itemformupdate.php +++ b/adm/shop_admin/itemformupdate.php @@ -304,6 +304,8 @@ foreach( $check_sanitize_keys as $key ){ $$key = isset($_POST[$key]) ? strip_tags(clean_xss_attributes($_POST[$key])) : ''; } +$it_basic = preg_replace('#(.*?)<\/script>#is', '', $it_basic); + if ($it_name == "") alert("상품명을 입력해 주십시오."); diff --git a/lib/shop.data.lib.php b/lib/shop.data.lib.php index 88e52fe02..d27fc0922 100644 --- a/lib/shop.data.lib.php +++ b/lib/shop.data.lib.php @@ -15,7 +15,8 @@ function get_shop_item($it_id, $is_cache=false, $add_query=''){ $g5_object->set('shop', $it_id, $item, $add_query_key); } - + + $item['it_basic'] = conv_content($item['it_basic'], 1); return $item; } @@ -29,7 +30,10 @@ function get_shop_item_with_category($it_id, $seo_title='', $add_query=''){ $sql = " select a.*, b.ca_name, b.ca_use from {$g5['g5_shop_item_table']} a, {$g5['g5_shop_category_table']} b where a.it_id = '$it_id' and a.ca_id = b.ca_id $add_query"; } - return sql_fetch($sql); + $item = sql_fetch($sql); + $item['it_basic'] = conv_content($item['it_basic'], 1); + + return $item; } function get_shop_navigation_data($is_cache, $ca_id, $ca_id2='', $ca_id3=''){ diff --git a/lib/shop.lib.php b/lib/shop.lib.php index e4fdb9d34..f48c3ca82 100644 --- a/lib/shop.lib.php +++ b/lib/shop.lib.php @@ -319,7 +319,8 @@ class item_list if( isset($row['it_seo_title']) && ! $row['it_seo_title'] ){ shop_seo_title_update($row['it_id']); } - + + $row['it_basic'] = conv_content($row['it_basic'], 1); $list[] = $row; }